Phishing Attack Bypasses Microsoft 365 MFA to Hijack a Finance Mailbox and Steal Payments
Phishing email bypasses MFA, compromising Microsoft 365 account to redirect payments. Learn how to protect against session cookie theft.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo